Claims and subclaims
State the bounded proposition and decompose it into independently reviewable dependencies.
Trace every assurance claim to its limits
Inspect how a bounded synthetic assurance case connects claims, evidence, assumptions, counterclaims, defeaters, verification, residual risk, accountable review, and invalidating change—without turning traceability into certification.
Research basis KW-RPT-011 KW-RPT-012 KW-RPT-014 KW-RPT-028
Reasoned argument, not a score
A claim graph is useful only when supporting evidence, contradictory evidence, assumptions, review responsibility, unresolved risk, and change triggers remain visible. Completing the graph does not prove that a real autonomous system is safe, ready, lawful, certified, or authorized.
Assurance-case anatomy
The public model uses one fixed catalog. It accepts no free-form claim, uploaded evidence, external URL, model file, platform record, target, or operational data.
State the bounded proposition and decompose it into independently reviewable dependencies.
Record provenance, date, independence group, scope, review state, and whether the record supports or contradicts.
Expose the environmental, authority, software, data, and human conditions on which the claim depends.
Preserve reasons the argument could be wrong and events that suspend or withdraw a claim.
Show what was actually tested, what must be rerun, and what remains unresolved after testing.
Name accountable roles and require re-review when software, models, configuration, authority, timing, sources, or mission bounds change.
Current top-level disposition
The fixed baseline remains a qualified, bounded teaching claim. Counterclaims, assumptions, and residual risks remain visible and prevent any certification inference.
Claim structure
A suspended or withdrawn dependency cannot be averaged away by unrelated technical evidence.
C-001Supported with qualificationsThe fictional autonomous support function can be relied upon only for observation, state estimation, recommendation, and already-approved non-force task coordination within the declared evidence, software, authority, supervision, containment, and recovery bounds.
E-001E-002E-012A-001A-007CC-001D-001C-010Supported within declared boundsThe function cannot silently expand beyond the declared non-force support tasks or change its own governance.
C-001E-001E-002A-001CC-001D-001C-020Supported with qualificationsEvery observation and derived product used by the function carries reviewable provenance, date, scope, transformation, and independence information.
C-001E-003E-004A-002CC-002D-002C-030Supported with qualificationsOnly signed, reviewed, compatible artifacts and declared configurations may contribute to the bounded function.
C-001E-005E-006A-003CC-003D-003D-008C-040Supported within declared boundsTechnical connectivity, model confidence, and task availability cannot create or renew authority.
C-001E-007A-004CC-004D-004C-050Supported with qualificationsA responsible reviewer has enough time, evidence access, comprehension, workload capacity, and intervention power to reject, pause, or redirect the function.
C-001E-008E-009A-005CC-005D-005C-060Supported within declared boundsSuspect inputs, artifacts, nodes, and dependent products can be isolated before they propagate into consequential action.
C-001E-010A-006D-006C-070Supported with qualificationsReconnection, rollback, or a new release cannot restore reliance until task ownership, timing, evidence, versions, authority, and claim dependencies are reconciled and re-reviewed.
C-001E-011E-012A-006A-007CC-006D-007Text alternative to the claim graph
The ledger prevents a visual connector from becoming the only way to understand why one record supports, qualifies, challenges, or invalidates another.
| From | Relationship | To |
|---|---|---|
E-001 | supports or qualifies | C-001 |
E-002 | supports or qualifies | C-001 |
E-012 | supports or qualifies | C-001 |
A-001 | bounds | C-001 |
A-007 | bounds | C-001 |
V-001 | tests | C-001 |
V-002 | tests | C-001 |
CC-001 | challenges | C-001 |
R-003 | qualifies | C-001 |
R-004 | qualifies | C-001 |
R-006 | qualifies | C-001 |
E-001 | supports or qualifies | C-010 |
E-002 | supports or qualifies | C-010 |
A-001 | bounds | C-010 |
V-001 | tests | C-010 |
V-002 | tests | C-010 |
CC-001 | challenges | C-010 |
R-003 | qualifies | C-010 |
E-003 | supports or qualifies | C-020 |
E-004 | supports or qualifies | C-020 |
A-002 | bounds | C-020 |
V-003 | tests | C-020 |
CC-002 | challenges | C-020 |
R-001 | qualifies | C-020 |
E-005 | supports or qualifies | C-030 |
E-006 | supports or qualifies | C-030 |
A-003 | bounds | C-030 |
V-004 | tests | C-030 |
CC-003 | challenges | C-030 |
R-005 | qualifies | C-030 |
E-007 | supports or qualifies | C-040 |
A-004 | bounds | C-040 |
V-005 | tests | C-040 |
CC-004 | challenges | C-040 |
R-004 | qualifies | C-040 |
E-008 | supports or qualifies | C-050 |
E-009 | supports or qualifies | C-050 |
A-005 | bounds | C-050 |
V-006 | tests | C-050 |
CC-005 | challenges | C-050 |
R-002 | qualifies | C-050 |
E-010 | supports or qualifies | C-060 |
A-006 | bounds | C-060 |
V-007 | tests | C-060 |
R-003 | qualifies | C-060 |
E-011 | supports or qualifies | C-070 |
E-012 | supports or qualifies | C-070 |
A-006 | bounds | C-070 |
A-007 | bounds | C-070 |
V-008 | tests | C-070 |
CC-006 | challenges | C-070 |
R-006 | qualifies | C-070 |
C-010 | supports parent | C-001 |
C-020 | supports parent | C-001 |
C-030 | supports parent | C-001 |
C-040 | supports parent | C-001 |
C-050 | supports parent | C-001 |
C-060 | supports parent | C-001 |
C-070 | supports parent | C-001 |
Evidence ledger
Support and contradiction can coexist. A current digest or signature does not prove relevance, independence, or fitness for a changed purpose.
| Evidence | Provenance and date | Independence | Scope | Supports / contradicts | Current state |
|---|---|---|---|---|---|
E-001Reviewed bounded-function contractDefines what the teaching system may and may not do; it creates no real authority. | Synthetic requirements registry2026-08-02 · review: reviewed | design-authority | Non-force support functions, excluded actions, safe states, and mission bounds. | Supports C-001C-010Contradicts None | currentThe record remains attached to the reviewed synthetic baseline. |
E-002Negative boundary and self-governance testsFixed negative tests confirm that prohibited requests are not accepted by the model. | Independent synthetic verification harness2026-08-02 · review: reviewed | independent-test | Requests for force selection, mission expansion, arbitrary claims, and governance change. | Supports C-001C-010Contradicts None | currentThe record remains attached to the reviewed synthetic baseline. |
E-003Evidence-lineage audit sampleShows complete lineage for the fixed baseline evidence set. | Synthetic data-steward ledger2026-08-02 · review: reviewed | data-governance | Source identity, time, transformation, review state, and permitted use. | Supports C-020Contradicts None | currentThe record remains attached to the reviewed synthetic baseline. |
E-004Source-independence and correlation reviewFinds adequate diversity for the exercise but leaves uncertainty about hidden common-mode dependence. | Independent assurance review2026-08-02 · review: provisional | independent-review | Common collection lineage and repeated reporting across the evidence set. | Supports C-020Contradicts C-020 | currentThe record remains attached to the reviewed synthetic baseline. |
E-005Signed artifact and configuration manifestIdentifies the approved baseline used by the fixed verification record. | Synthetic approved-update registry2026-08-02 · review: reviewed | change-control | Software, model, configuration, dependency, signature, and rollback identifiers. | Supports C-030Contradicts None | currentThe record remains attached to the reviewed synthetic baseline. |
E-006Mixed-version and rollback exerciseThe system detected the fixed version split, but unseen combinations remain outside the evidence. | Independent failure-injection lab2026-08-02 · review: reviewed | independent-test | Version mismatch detection, rollback, and dependent-product invalidation. | Supports C-030Contradicts C-030 | currentThe record remains attached to the reviewed synthetic baseline. |
E-007Authority expiry and revocation testThe fixed model holds the function when the authority record expires. | Synthetic authority-gate verification2026-08-02 · review: reviewed | authority-review | Scope, expiry, revocation, and separation of capability from permission. | Supports C-040Contradicts None | currentThe record remains attached to the reviewed synthetic baseline. |
E-008Timed reviewer intervention trialA reviewer can interrupt the fixed baseline workflow under the tested workload and timing. | Synthetic human-factors evaluation2026-08-02 · review: reviewed | human-factors | Evidence access, comprehension prompt, pause, reject, and redirect controls. | Supports C-050Contradicts None | currentThe record remains attached to the reviewed synthetic baseline. |
E-009Overload and compressed-review challengeDemonstrates that nominal human-on-the-loop control can fail under workload and time pressure. | Independent human-factors red team2026-08-02 · review: reviewed | independent-review | High alert volume, short intervention window, and evidence-ordering effects. | Supports None Contradicts C-050 | currentThe record remains attached to the reviewed synthetic baseline. |
E-010Quarantine and dependent-product invalidation exerciseThe fixed scenario isolates a suspect artifact and invalidates dependent outputs. | Synthetic cybersecurity test harness2026-08-02 · review: reviewed | independent-test | Suspect update isolation, product lineage tracing, rollback, and safe-state entry. | Supports C-060Contradicts None | currentThe record remains attached to the reviewed synthetic baseline. |
E-011Partition rejoin and task-ownership reconciliation exerciseThe fixed model requires reconciliation before shared operation resumes. | Synthetic autonomy-assurance lab2026-08-02 · review: reviewed | independent-test | Task leases, clocks, authority, versions, state conflicts, and rejoin acknowledgment. | Supports C-070Contradicts None | currentThe record remains attached to the reviewed synthetic baseline. |
E-012Residual-unknown and review-responsibility recordPrevents completion of the traceability graph from being represented as certification. | Independent assurance review2026-08-02 · review: reviewed | independent-review | Unresolved unknowns, accountable reviewers, and re-review triggers. | Supports C-001C-070Contradicts None | currentThe record remains attached to the reviewed synthetic baseline. |
Limits and challenge
They are not footnotes to be hidden after the positive argument.
A-001currentNo target selection, weapon assignment, force authorization, or governance expansion.
The declared assumption has not been invalidated by the selected change set.A-002currentNo silent data-source substitution, transformation change, or loss of provenance.
The declared assumption has not been invalidated by the selected change set.A-003currentSoftware, model, configuration, dependency, and rollback identifiers match the tested baseline.
The declared assumption has not been invalidated by the selected change set.A-004currentThe authority record has not expired, been revoked, or been applied outside its declared function.
The declared assumption has not been invalidated by the selected change set.A-005currentThe reviewer has adequate time, evidence access, comprehension, and interruption power.
The declared assumption has not been invalidated by the selected change set.A-006currentSafe state, quarantine, rollback, signed logs, and rejoin controls are reachable.
The declared assumption has not been invalidated by the selected change set.A-007currentThe public synthetic model does not represent all environmental, organizational, or legal conditions.
The declared assumption has not been invalidated by the selected change set.CC-001challengeA system may complete the demonstrated task while still containing untested pathways or hidden scope expansion.
ChallengesC-001C-010CC-002challengeTwo apparently separate reports can depend on one collection stream or transformation service.
ChallengesC-020CC-003challengeAuthenticity proves origin and integrity, not correctness, compatibility, or fitness for the changed context.
ChallengesC-030CC-004challengeA technically valid record does not apply after expiry, revocation, or mission-bound change.
ChallengesC-040CC-005challengeAn operator cannot exercise meaningful judgment without enough time, evidence, capacity, and rejection power.
ChallengesC-050CC-006challengeA restored link does not renew authority, resolve duplicate ownership, repair lineage, or validate products created while partitioned.
ChallengesC-070Invalidating change
Software, model, configuration, authority, timing, source, mission-bound, human-control, containment, and reconciliation changes each have their own review impact.
BASELINEmonitoredThe qualified baseline still depends on continued monitoring of every declared trigger.
NONEbaselineCounterclaims and residual risks remain active qualifications even when no hard defeater is selected.
Verification and residual risk
Every changed dependency identifies which activity must be rerun and which uncertainty remains outside the fixed exercise.
V-001passedReview the declared function, exclusions, authority boundary, and safe states.
The recorded result applies only to the reviewed baseline.V-002passedSubmit fixed prohibited requests and verify rejection without server state or external calls.
The recorded result applies only to the reviewed baseline.V-003qualifiedTrace source, time, transformation, review, and independence group for each evidence record.
The recorded result applies only to the reviewed baseline.V-004qualifiedVerify signed baseline, mixed-version detection, rollback, and dependent-output invalidation.
The recorded result applies only to the reviewed baseline.V-005passedExpire or revoke the fixed authority record and verify that technical recovery cannot renew it.
The recorded result applies only to the reviewed baseline.V-006qualifiedMeasure evidence access, comprehension, workload, pause, reject, and redirect under fixed conditions.
The recorded result applies only to the reviewed baseline.V-007passedInject a suspect artifact and verify isolation, hold, rollback, and dependent-product tracing.
The recorded result applies only to the reviewed baseline.V-008qualifiedCompare signed state, task leases, clocks, versions, authority, and claim dependencies before resumption.
The recorded result applies only to the reviewed baseline.R-001retainedPublic metadata may not reveal every shared collection or transformation dependency.
Retain as an explicit limitation and seek genuinely independent corroboration.R-002retainedWorkload, fatigue, experience, interface familiarity, and stress can change intervention quality.
Use recurring human-factors testing and conservative hold thresholds.R-003retainedA finite synthetic case cannot cover every combination of node, change, failure, and organizational response.
Maintain abstention, monitoring, containment, and independent red-team testing.R-004retainedTechnical evidence cannot determine real-world lawfulness, target status, proportionality, or command permission.
Require separate accountable legal and command review for any real system.R-005retainedThe synthetic manifest cannot establish real hardware, firmware, model, or supplier integrity.
Use authentic provenance, reproducible builds, inspection, and continuous monitoring in real assurance.R-006retainedA valid case can become stale when data sources, tempo, environment, authorities, or mission bounds change.
Monitor declared change triggers and suspend reliance until re-review.Accountable review
The selected change set determines which reviewers must participate before a suspended claim can return to a current state.
case-ownerMaintains claim scope, dependencies, review state, and withdrawal decisions.
independent-reviewerChallenges the reasoning, checks traceability, and confirms that counterevidence is not hidden.
Lifecycle method
The case must be monitored, challenged, suspended, revised, and sometimes withdrawn as its dependencies change.
State the exact function, environment, consequence, evidence threshold, authority, and excluded use.
Connect each subclaim to evidence, assumptions, counterclaims, defeaters, verification, residual risks, and reviewers.
Seek contradictory evidence, common-mode dependence, negative cases, and failure conditions rather than confirmation alone.
Watch software, model, configuration, authority, timing, source, mission, human-control, and recovery contracts.
Stop relying on affected claims before re-review; do not allow an old report to authorize a changed system.
Rerun affected verification, resolve counterevidence, record residual risk, and obtain explicit reviewer decisions.
Answer-ready summary
It is a maintained, reviewable argument connecting a bounded top-level claim to subclaims, evidence, assumptions, challenges, verification, residual risk, accountable reviewers, and events that invalidate the argument.
Read the supporting pageThe affected evidence, assumptions, and tests are marked invalid or out of scope; dependent claims are suspended or withdrawn; and named reviewers must complete re-review before reliance resumes.
Read the supporting pageNo. Traceability organizes reasoning and makes its limits visible. It does not create certification, compliance, readiness, safety, legality, mission success, target confidence, or force authority.
Read the supporting page